Threats Tagged 't1091'
View all threats tagged with 't1091'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1091'
Click on any threat for detailed analysis and mitigation recommendations
On August 31, 2026, U.S., Bulgarian, Hungarian, and Romanian authorities, collaborating with CrowdStrike and Shadowserver Foundation, successfully disrupted the Sality botnet through a peer-to-peer sinkhole operation. Active since 2003, Sality infects Windows executables and spreads malware for credential theft, spam distribution, and DDoS attacks. The botnet delivered EggJagger clipper malware, stealing at least $150,000 through cryptocurrency wallet substitution. The takedown exploited Sality's P2P architecture weakness by manipulating peer lists, isolating over 15,000 infected machines from threat actor control. This peer list manipulation technique prevented payload distribution by inserting sinkhole entries and removing legitimate peers. Associated domains were seized across U.S. and Europe. While the disruption stops new payloads, existing infections remain active requiring remediation. The operation demonstrates that resilient P2P criminal infrastructure can be dismantled through coordinated law enf... Join the discussion | AlienVault OTX General | 09/02/2026, 09:56:00 UTC Added: 09/02/2026, 11:37:30 UTC |
A Windows-based cryptocurrency clipper has been actively targeting users since February 2026, employing sophisticated techniques to steal digital assets. The malware propagates through malicious shortcut files on USB devices, creating a worm-like infection chain. Once deployed, it utilizes Windows Script Host and ActiveX to launch a bundled Tor proxy client, enabling anonymous communication with hidden-service command and control servers. The clipper performs high-frequency clipboard monitoring to intercept cryptocurrency wallet addresses, seed phrases, and private keys, replacing them with attacker-controlled alternatives. Additionally, it captures screenshots for context and maintains persistent access through scheduled tasks. The threat demonstrates advanced capabilities including remote code execution, making it more than a simple stealer by functioning as a lightweight backdoor. The malware employs multiple defense evasion techniques including multi-layer obfuscation, anti-analysis checks, and local S... Join the discussion | AlienVault OTX General | 06/18/2026, 03:14:19 UTC Added: 06/18/2026, 14:37:05 UTC |
ZionSiphon is operational technology-focused malware targeting water treatment and desalination facilities in Israel. The sample demonstrates ICS-awareness through industrial protocol interaction capabilities including Modbus, with incomplete support for DNP3 and S7comm. It incorporates geographic and environmental validation controls designed to restrict execution to Israeli water infrastructure systems. The malware attempts persistence through registry autorun entries, privilege escalation, and removable media propagation. Functionality includes network discovery of industrial devices, process manipulation targeting chlorine dosing and flow control, and configuration file modification. A critical validation flaw prevents successful execution, suggesting the analyzed sample represents incomplete development or testing. Embedded pro-Iran and anti-Israel messaging indicates politically motivated intent, though no specific threat actor attribution exists. Join the discussion | AlienVault OTX General | 04/28/2026, 08:11:57 UTC Added: 04/28/2026, 14:06:21 UTC |
A South Asian financial institution was targeted with two custom malware components: BRUSHWORM, a modular backdoor, and BRUSHLOGGER, a keylogger. BRUSHWORM features anti-analysis checks, encrypted configuration, scheduled task persistence, modular payload downloading, USB worm propagation, and extensive file theft. BRUSHLOGGER uses DLL side-loading to capture system-wide keystrokes with window context tracking. The malware's low sophistication and implementation flaws suggest an inexperienced author, possibly using AI code-generation tools. Multiple testing versions were discovered on VirusTotal, indicating iterative development. The malware components combine to create a functional collection platform with modular loading, USB propagation, broad file theft, air-gap bridging, and persistent keystroke capture. Join the discussion | AlienVault OTX General | 03/27/2026, 08:45:50 UTC Added: 03/27/2026, 09:44:44 UTC |
Tangerine Turkey is a cryptomining campaign that propagates via VBScript worms spread through USB drives, leveraging legitimate system binaries for execution and persistence. The malware employs advanced defense evasion techniques such as registry modification and masquerading malicious files as legitimate system components. It establishes persistence through malicious services and scheduled tasks while attempting to disable Windows Defender. Although its primary objective is unauthorized cryptocurrency mining, its capabilities for persistence and lateral movement pose broader security risks. The campaign uses living-off-the-land binaries and creates mock directories to conceal its activities. No known CVEs or exploits are currently associated with this threat. The medium severity rating reflects the financial motivation and potential for system compromise without immediate destructive impact. European organizations using Windows systems with USB access are at risk, especially those with lax endpoint security controls and high-value targets. Mitigation requires targeted controls beyond generic advice, including USB device management, monitoring for living-off-the-land abuse, and registry integrity checks. Join the discussion | AlienVault OTX General | 10/29/2025, 18:37:29 UTC Added: 10/29/2025, 20:13:19 UTC |
In mid-2025, China-aligned threat actor Hive0154 deployed new malware variants, including an updated Toneshell backdoor and a novel USB worm called SnakeDisk. Toneshell9 evades detection and supports C2 communication through local proxies. SnakeDisk only executes on devices in Thailand, propagating via USB drives and dropping the Yokai backdoor. The malware shows code overlaps with previous Tonedisk variants. Hive0154 continues to refine its large malware arsenal, targeting organizations worldwide with frequent development cycles. The group uses multiple custom loaders, backdoors, and USB worm families, showcasing advanced capabilities. Defenders should monitor for suspicious network activity, USB drives with hidden components, and implement recommended security measures to mitigate risks from this evolving threat. Join the discussion | AlienVault OTX General | 09/11/2025, 19:39:20 UTC Added: 09/11/2025, 19:59:54 UTC |
An analysis reveals a recent attack vector targeting WordPress themes, specifically injecting malicious code into the footer.php file. The injected code uses a function called r2048 to retrieve a URL from a remote server and redirect visitors. This method is particularly insidious as it's not visible from the WordPress dashboard. The attackers utilize either cURL or file_get_contents to fetch the redirection URL, allowing for dynamic control over the destination based on factors like the user's browser or device. This technique underscores the importance of regular theme and plugin audits, as well as securing FTP and SSH access to prevent unauthorized file modifications. Join the discussion | AlienVault OTX General | 07/11/2025, 06:42:39 UTC Added: 07/11/2025, 11:16:06 UTC |
Showing 1 to 7 of 7 results